Glossary · Security and access

Authorization

The rules and decisions that determine which resources or actions an authenticated identity may use.

Also called: access control

Definition

Authorization can be based on roles, ownership, scope, policy, or specific grants. It should give people and services only the access required for their work and should be reviewed when responsibilities change.

Why it matters

Correct authorization limits the effect of mistakes, compromised accounts, and unnecessary vendor access.

Common misunderstanding

A successful login does not mean the user should have access to every account, record, or administrative action.

Related system family: Secure Integrations & Custom Tools

Sources

Last reviewed July 16, 2026

Return to the complete glossary